<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 23:50:55 +0000</lastBuildDate>
    <item>
      <title>bdu:2023-04933</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2023-04933</link>
      <description>bdu:2023-04933</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2023-04933</guid>
    </item>
    <item>
      <title>EUVD-2026-193780</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-193780</link>
      <description>EUVD-2026-193780</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-193780</guid>
    </item>
    <item>
      <title>fkie_cve-2023-37857</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2023-37857</link>
      <description>&lt;p&gt;In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 an authenticated, remote attacker with admin privileges is able to read hardcoded cryptographic keys allowing the attacker to create valid session cookies.  These session-cookies created by the attacker are not sufficient to obtain a valid session on the device.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 an authenticated, remote attacker with admin privileges is able to read hardcoded cryptographic keys allowing the attacker to create valid session cookies.  These session-cookies created by the attacker are not sufficient to obtain a valid session on the device.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2023-37857</guid>
    </item>
    <item>
      <title>GHSA-rq33-29r2-6jr3</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-rq33-29r2-6jr3</link>
      <description>&lt;p&gt;In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 an authenticated, remote attacker with admin privileges is able to read hardcoded cryptographic keys allowing the attacker to create valid session cookies. This issue cannot be exploited to bypass the web service authentication of the affected device(s).&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 an authenticated, remote attacker with admin privileges is able to read hardcoded cryptographic keys allowing the attacker to create valid session cookies. This issue cannot be exploited to bypass the web service authentication of the affected device(s).&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-rq33-29r2-6jr3</guid>
    </item>
    <item>
      <title>gsd-2023-37857</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2023-37857</link>
      <description>gsd-2023-37857</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2023-37857</guid>
    </item>
    <item>
      <title>VDE-2023-018 — Phoenix Contact: Multiple vulnerabilities in WP 6xxx Web panels</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2023-018</link>
      <description>&lt;p&gt;Multiple vulnerabilities allow an attacker to read arbitrary files, inject commands and bypass authentication or access control. Furthermore, hardcoded session and encryption keys as well as a missing firmware update signature and a service running with unnecessary privileges were discovered.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Multiple vulnerabilities allow an attacker to read arbitrary files, inject commands and bypass authentication or access control. Furthermore, hardcoded session and encryption keys as well as a missing firmware update signature and a service running with unnecessary privileges were discovered.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2023-018</guid>
    </item>
  </channel>
</rss>
